17 Gru 2011, 03:22
17 Gru 2011, 17:28
:OTL
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: D:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: D:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: D:\Documents and Settings\konrad\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: D:\Documents and Settings\konrad\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O15 - HKU\S-1-5-21-861567501-2077806209-682003330-1003\..Trusted Domains: ([]msn in My Computer)
@Alternate Data Stream - 154 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:CB0AACC9
@Alternate Data Stream - 134 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:671329E4
@Alternate Data Stream - 121 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:CE2C623F
@Alternate Data Stream - 118 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:0B4227B4
@Alternate Data Stream - 117 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:C43ED645
:Files
D:\Program Files\Google\Update
D:\Documents and Settings\konrad\Ustawienia lokalne\Dane aplikacji\Google\Update
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-861567501-2077806209-682003330-1003UA.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\SA.DAT
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-861567501-2077806209-682003330-1003Core.job
D:\Documents and Settings\konrad\Dane aplikacji\.#
I:\Super
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=-
:Commands
[clearallrestorepoints]
[emptytemp]
17 Gru 2011, 19:37
17 Gru 2011, 20:52
:OTL
O4 - HKU\S-1-5-21-861567501-2077806209-682003330-1003..\Run: [SUPERAntiSpyware] I:\Super\SUPERAntiSpyware.exe File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - I:\Super\SASSEH.DLL File not found
:Services
gupdatem
gupdate
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{695B13B2-7919-4EC5-8601-092F0D2DE069}"=-
17 Gru 2011, 20:54
:OTL
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: D:\Documents and Settings\konrad\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
O4 - HKU\S-1-5-21-861567501-2077806209-682003330-1003..\Run: [SUPERAntiSpyware] I:\Super\SUPERAntiSpyware.exe File not found
O15 - HKU\S-1-5-21-861567501-2077806209-682003330-1003\..Trusted Domains: ([]msn in My Computer)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - I:\Super\SASSEH.DLL File not found
@Alternate Data Stream - 154 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:CB0AACC9
@Alternate Data Stream - 134 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:671329E4
@Alternate Data Stream - 121 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:CE2C623F
@Alternate Data Stream - 118 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:0B4227B4
@Alternate Data Stream - 117 bytes D:\Documents and Settings\All Users\Dane aplikacji\TEMP:C43ED645
:Services
gupdatem
gupdate
:Files
I:\Super
D:\WINDOWS\tasks\SA.DAT
D:\Documents and Settings\konrad\Dane aplikacji\thecleaner
:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{20EAC554-95F9-4926-8D9A-C4FF3EC44C72}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{695B13B2-7919-4EC5-8601-092F0D2DE069}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}]
:Commands
[clearallrestorepoints]
[emptytemp]
17 Gru 2011, 21:33
17 Gru 2011, 22:16
:Processes
killallprocesses
:OTL
O15 - HKU\S-1-5-21-861567501-2077806209-682003330-1003\..Trusted Domains: ([]msn in My Computer)
:Files
D:\WINDOWS\tasks\SA.DAT
:Commands
[clearallrestorepoints]
[emptytemp]
17 Gru 2011, 22:48
18 Gru 2011, 19:12
19 Gru 2011, 16:25
19 Gru 2011, 18:45